Bitget Hack Explained: How Lazarus Group Used A Fake Job Interview To Steal Millions

Last Updated:
Bitget Hack Explained: How Lazarus Group Used A Fake Job Interview To Steal Millions
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Lazarus Group used a fake job interview to breach Bitget’s wallet systems fully.
  • Bitget’s $464 million Protection Fund will cover the entire financial hack loss.
  • Bitget said all cold wallets stay fully untouched under the three-layer systems.

Bitget’s security systems picked up unusual transfers from its hot wallets at 18:31 UTC on September 24. Within minutes, the company activated its emergency response and froze withdrawals across the platform while it worked out what had happened.

The company said the attackers never stole a private key and never broke through Bitget’s core encryption. Instead, they got in through a backend system inside the wallet infrastructure, using it to fake transaction data and trick the platform’s own authorization process into approving fund transfers that should never have gone through.

Chen said the entry point was human, not technical. The attackers built a fake job opportunity, approaching a Bitget employee with what looked like a genuine hiring process. Over the course of the interview, the attackers worked to build trust and make the process feel routine and comfortable. Once that trust was in place, they used the relationship to extract sensitive internal information, which they later used to access the backend system.

Why This Method Works

Social engineering attacks like this do not rely on breaking code. They rely on breaking judgment. A well-run fake interview can look identical to a real one. A recruiter reaches out, schedules calls, asks technical questions, and shares documents or coding tasks. Somewhere in that process, the target is asked to open a file, run a script, or share access details that seem like a normal part of a job application.

Lazarus Group, the North Korea-linked hacking operation Chen named, has used this exact playbook against crypto companies before. Security researchers have repeatedly flagged fake recruiter outreach on LinkedIn and other platforms as one of the group’s preferred ways into crypto firms, precisely because it targets people instead of firewalls.

What Bitget Says Is Safe

Bitget said its wallet system is split into three layers, and only parts of the hot and warm wallet layers were touched. All cold wallets, which hold funds offline and are harder to reach, remained untouched. The exchange said no further unauthorized transfers are possible and that the breach has been contained.

User balances remain accurate, Bitget said, and the entire loss is covered by its User Protection Fund, which holds more than $464 million. Deposits and trading continued normally throughout, and Bitget Wallet, the exchange’s separate self-custodial product, was unaffected since it runs on independent infrastructure.

Cybersecurity firms Mandiant and SlowMist are assisting with the investigation. Bitget said the exact technical details of how the backend was first accessed are still being confirmed, and a full report will follow once that work is complete.

What Happens Next

Withdrawals are being restored in phases rather than all at once, starting September 28 with Bitcoin and finishing October 2 with all remaining tokens, fiat and P2P transfers. Chen said she would host a live session on September 28 to walk through what happened and answer questions directly from users.

Related: Birmingham Crypto Robbery: £10,000 Reward Offered for Information

Related: Bitget Traces $387.5M Crypto Incident, Plans Withdrawal Update by Sept. 26

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.